ThreatBox · Threat Actor Attribution
APT28
a.k.a. Fancy Bear, Sofacy, STRONTIUM, Forest Blizzard, Pawn Storm, GRU Unit 26165
Espionage (state-sponsored, military intelligence) Russia (GRU Military Intelligence) First seen 2004
APT28 is Russia's GRU (military intelligence) cyber unit, tasked with strategic espionage and information operations. Best known for the 2016 DNC hack and the TV5Monde attack (2015). Continues to run credential-phishing at scale against military/government targets, especially in Ukraine post-2022. Uses custom malware (X-Agent, Zebrocy, HeadLace) and heavy exploitation of Outlook/Roundcube CVEs.
Targeted sectors
GovernmentMilitaryDefense contractorsMediaPolitical organisations
Targeted regions
NATO countriesUkraineGeorgia
Known TTPs (4)
T1566.002Spearphishing Link
T1190Exploit Public-Facing Application
T1550.002Pass the Hash
T1114.002Remote Email Collection
Click any technique to open the MITRE ATT&CK reference.
Attack Timeline
- 2015-04TV5Monde broadcast disruption
- 2016-07DNC email leak (US election interference)
- 2018-07Mueller indictment of 12 GRU officers
- 2023-03CVE-2023-23397 Outlook zero-day mass-exploitation (Ukraine targets)
References
End of dossier · APT28
Back to ThreatBox